openapi: 3.2.0 info: title: Aembit Cloud Access Condition v2 API version: v1 servers: - url: https://{tenant}.aembit.io variables: tenant: default: tenant description: Aembit Tenant ID security: - {} tags: - name: Access Condition v2 paths: /api/v2/access-conditions: get: tags: - Access Condition v2 summary: Get a page of Access Conditions description: Retrieve a page of Aembit Access Conditions. operationId: get-access-conditions2 parameters: - name: X-Aembit-ResourceSet in: header schema: type: string format: uuid - name: page in: query schema: type: integer format: int32 default: 1 - name: per-page in: query schema: type: integer format: int32 default: 100 - name: filter in: query schema: type: string default: '' - name: order in: query schema: type: string default: '' - name: group-by in: query schema: type: string default: '' responses: '200': description: Page of Access Conditions content: application/json: schema: description: Page of Access Conditions $ref: '#/components/schemas/AccessConditionV2DTOAccessConditionListDTO' '400': description: Bad Request '401': description: Not Authenticated '500': description: Internal Server Error content: application/json: schema: description: DTO for a Generic API Response $ref: '#/components/schemas/GenericResponseDTO' post: tags: - Access Condition v2 summary: Create an Access Condition description: Create an Aembit Access Condition which can then be associated with an Access Policy. operationId: post-access-condition2 parameters: - name: X-Aembit-ResourceSet in: header schema: type: string format: uuid requestBody: description: AccessConditionV2DTO content: application/json: schema: oneOf: - $ref: '#/components/schemas/AccessConditionV2DTO' - $ref: '#/components/schemas/CrowdStrikeAccessConditionDTO' - $ref: '#/components/schemas/WizAccessConditionDTO' - $ref: '#/components/schemas/GeoIPAccessConditionDTO' - $ref: '#/components/schemas/TimeAccessConditionDTO' responses: '201': description: Successfully created Access Condition content: application/json: schema: oneOf: - $ref: '#/components/schemas/AccessConditionV2DTO' - $ref: '#/components/schemas/CrowdStrikeAccessConditionDTO' - $ref: '#/components/schemas/WizAccessConditionDTO' - $ref: '#/components/schemas/GeoIPAccessConditionDTO' - $ref: '#/components/schemas/TimeAccessConditionDTO' '400': description: Bad Request '401': description: Not Authenticated '500': description: Internal Server Error content: application/json: schema: description: DTO for a Generic API Response $ref: '#/components/schemas/GenericResponseDTO' put: tags: - Access Condition v2 summary: Update a single Access Condition description: Update a specific Access Condition identified by its ID. operationId: put-access-condition2 parameters: - name: X-Aembit-ResourceSet in: header schema: type: string format: uuid requestBody: description: AccessConditionDTO content: application/json: schema: oneOf: - $ref: '#/components/schemas/AccessConditionV2DTO' - $ref: '#/components/schemas/CrowdStrikeAccessConditionDTO' - $ref: '#/components/schemas/WizAccessConditionDTO' - $ref: '#/components/schemas/GeoIPAccessConditionDTO' - $ref: '#/components/schemas/TimeAccessConditionDTO' responses: '200': description: Successfully updated Access Condition content: application/json: schema: oneOf: - $ref: '#/components/schemas/AccessConditionV2DTO' - $ref: '#/components/schemas/CrowdStrikeAccessConditionDTO' - $ref: '#/components/schemas/WizAccessConditionDTO' - $ref: '#/components/schemas/GeoIPAccessConditionDTO' - $ref: '#/components/schemas/TimeAccessConditionDTO' '400': description: Bad Request '401': description: Not Authenticated '500': description: Internal Server Error content: application/json: schema: description: DTO for a Generic API Response $ref: '#/components/schemas/GenericResponseDTO' /api/v2/access-conditions/{id}: get: tags: - Access Condition v2 summary: Get the identified Access Condition description: Get the Access Condition identified by its ID. operationId: get-access-condition2 parameters: - name: id in: path description: ID of Access Condition required: true schema: type: string format: uuid - name: X-Aembit-ResourceSet in: header schema: type: string format: uuid responses: '200': description: Access Condition content: application/json: schema: oneOf: - $ref: '#/components/schemas/AccessConditionV2DTO' - $ref: '#/components/schemas/CrowdStrikeAccessConditionDTO' - $ref: '#/components/schemas/WizAccessConditionDTO' - $ref: '#/components/schemas/GeoIPAccessConditionDTO' - $ref: '#/components/schemas/TimeAccessConditionDTO' '204': description: Access Condition Not Found '400': description: Bad Request '401': description: Not Authenticated '500': description: Internal Server Error content: application/json: schema: description: DTO for a Generic API Response $ref: '#/components/schemas/GenericResponseDTO' delete: tags: - Access Condition v2 summary: Delete a single Access Condition description: Delete a specific Access Condition identified by its ID. operationId: delete-access-condition2 parameters: - name: id in: path description: ID of Access Condition required: true schema: type: string format: uuid - name: X-Aembit-ResourceSet in: header schema: type: string format: uuid responses: '204': description: Deleted the Access Condition '400': description: Bad Request '401': description: Not Authenticated '404': description: Not Found '500': description: Internal Server Error content: application/json: schema: description: DTO for a Generic API Response $ref: '#/components/schemas/GenericResponseDTO' patch: tags: - Access Condition v2 summary: Patch a single Access Condition description: Patch a specific Access Condition identified by its ID. operationId: patch-access-condition2 parameters: - name: id in: path description: ID of Access Condition required: true schema: type: string format: uuid - name: X-Aembit-ResourceSet in: header schema: type: string format: uuid requestBody: description: AccessConditionPatchDTO content: application/json: schema: description: Patch Request DTO for individual Access Condition $ref: '#/components/schemas/AccessConditionPatchDTO' responses: '200': description: Successfully updated Access Condition content: application/json: schema: oneOf: - $ref: '#/components/schemas/AccessConditionV2DTO' - $ref: '#/components/schemas/CrowdStrikeAccessConditionDTO' - $ref: '#/components/schemas/WizAccessConditionDTO' - $ref: '#/components/schemas/GeoIPAccessConditionDTO' - $ref: '#/components/schemas/TimeAccessConditionDTO' '400': description: Bad Request '401': description: Not Authenticated '500': description: Internal Server Error content: application/json: schema: description: DTO for a Generic API Response $ref: '#/components/schemas/GenericResponseDTO' components: schemas: GeoIPAccessConditionLocationDTO: required: - shortName type: object properties: id: type: integer format: int32 shortName: minLength: 1 type: string alpha2Code: type: - 'null' - string subdivisions: type: - 'null' - array items: $ref: '#/components/schemas/GeoIPAccessConditionSubdivisionDTO' geoIPAccessConditionId: type: integer format: int32 additionalProperties: false CrowdStrikeIntegrationDTO: allOf: - $ref: '#/components/schemas/IntegrationV2DTO' - type: object properties: clientId: type: - 'null' - string tokenUrl: type: - 'null' - string clientSecret: type: - 'null' - string audience: type: - 'null' - string additionalProperties: false description: Integration details for 3rd party data used by Access Conditions CrowdStrikeAccessConditionDTO: allOf: - $ref: '#/components/schemas/AccessConditionV2DTO' - type: object properties: matchLocalIP: type: boolean matchHostname: type: boolean matchMacAddress: type: boolean matchSerialNumber: type: boolean preventRestrictedFunctionalityMode: type: boolean additionalProperties: false GeoIPAccessConditionDTO: allOf: - $ref: '#/components/schemas/AccessConditionV2DTO' - type: object properties: locations: type: - 'null' - array items: $ref: '#/components/schemas/GeoIPAccessConditionLocationDTO' additionalProperties: false WizAccessConditionDTO: allOf: - $ref: '#/components/schemas/AccessConditionV2DTO' - type: object properties: serverless: type: boolean containerClusterConnected: type: boolean additionalProperties: false GeoIPIntegrationDTO: allOf: - $ref: '#/components/schemas/IntegrationV2DTO' - type: object additionalProperties: false description: Integration details for 3rd party data used by Access Conditions AccessConditionV2DTO: required: - integrationType - isActive - name - resourceSet type: object properties: integrationType: type: - 'null' - string externalId: type: string format: uuid name: maxLength: 128 minLength: 1 type: string description: Name of the Entity description: type: - 'null' - string description: Description of the Entity isActive: type: boolean description: True/False value that determines if this entity is Active or Disabled format: boolean tags: type: - 'null' - array items: description: Aembit Entity Tag Details $ref: '#/components/schemas/TagDTO' createdAt: type: string format: date-time modifiedAt: type: - 'null' - string format: date-time createdBy: type: - 'null' - string modifiedBy: type: - 'null' - string resourceSet: type: string description: ID of the Resource Set in which this Access Entity exists format: uuid integrationID: type: string description: ID of the Integration Entity used by this Access Condition format: uuid integration: type: 'null' oneOf: - description: Integration details for 3rd party data used by Access Conditions $ref: '#/components/schemas/IntegrationV2DTO' - $ref: '#/components/schemas/CrowdStrikeIntegrationDTO' - $ref: '#/components/schemas/WizIntegrationDTO' - $ref: '#/components/schemas/GeoIPIntegrationDTO' - $ref: '#/components/schemas/TimeIntegrationDTO' description: Integration Entity used by this Access Condition maxLastSeenSeconds: type: integer format: int32 accessPolicyCount: type: integer description: Access Policies associated with this Access Condition format: int32 additionalProperties: false discriminator: propertyName: integrationType mapping: CrowdStrike: '#/components/schemas/CrowdStrikeAccessConditionDTO' WizIntegrationApi: '#/components/schemas/WizAccessConditionDTO' AembitGeoIPCondition: '#/components/schemas/GeoIPAccessConditionDTO' AembitTimeCondition: '#/components/schemas/TimeAccessConditionDTO' WeekDayDTO: type: object properties: name: type: - 'null' - string ordinal: type: integer format: int32 additionalProperties: false GenericResponseDTO: type: object properties: success: type: boolean description: True if the API call was successful, False otherwise message: type: - 'null' - string description: Message to indicate why the API call failed id: type: integer description: Unique identifier of the API response format: int32 additionalProperties: false description: DTO for a Generic API Response TimeAccessConditionDTO: allOf: - $ref: '#/components/schemas/AccessConditionV2DTO' - type: object properties: schedule: type: - 'null' - array items: $ref: '#/components/schemas/TimeAccessConditionScheduleDTO' timezone: $ref: '#/components/schemas/TimeAccessConditionTimezoneDTO' additionalProperties: false AccessConditionPatchDTO: type: object properties: name: maxLength: 128 type: - 'null' - string description: New Name for the identified entity description: type: - 'null' - string description: New Description for the identified entity isActive: type: - 'null' - boolean description: New Status for the identified entity format: boolean tags: type: - 'null' - array items: description: Aembit Entity Tag Details $ref: '#/components/schemas/TagDTO' description: New Tags for the identified entity additionalProperties: false description: Patch Request DTO for individual Access Condition TagDTO: required: - key - value type: object properties: key: minLength: 1 type: string description: Tag Key value: minLength: 1 type: string description: Tag Key Value additionalProperties: false description: Aembit Entity Tag Details TimeAccessConditionTimezoneDTO: type: object properties: group: type: - 'null' - string label: type: - 'null' - string timezone: type: - 'null' - string additionalProperties: false WizIntegrationDTO: allOf: - $ref: '#/components/schemas/IntegrationV2DTO' - type: object properties: clientId: type: - 'null' - string tokenUrl: type: - 'null' - string clientSecret: type: - 'null' - string audience: type: - 'null' - string additionalProperties: false description: Integration details for 3rd party data used by Access Conditions GeoIPAccessConditionSubdivisionDTO: required: - name type: object properties: id: type: integer format: int32 name: minLength: 1 type: string alpha2Code: type: - 'null' - string subdivisionCode: type: - 'null' - string geoIPAccessConditionLocationId: type: integer format: int32 additionalProperties: false TimeIntegrationDTO: allOf: - $ref: '#/components/schemas/IntegrationV2DTO' - type: object additionalProperties: false description: Integration details for 3rd party data used by Access Conditions IntegrationV2DTO: required: - endpoint - integrationType - isActive - name - resourceSet - syncFrequencySeconds - type type: object properties: integrationType: type: - 'null' - string externalId: type: string format: uuid name: maxLength: 128 minLength: 1 type: string description: Name of the Entity description: type: - 'null' - string description: Description of the Entity isActive: type: boolean description: True/False value that determines if this entity is Active or Disabled format: boolean tags: type: - 'null' - array items: description: Aembit Entity Tag Details $ref: '#/components/schemas/TagDTO' createdAt: type: string format: date-time modifiedAt: type: - 'null' - string format: date-time createdBy: type: - 'null' - string modifiedBy: type: - 'null' - string resourceSet: type: string description: ID of the Resource Set in which this Access Entity exists format: uuid type: minLength: 1 type: string syncFrequencySeconds: maximum: 3600 minimum: 300 type: integer format: int32 lastSync: type: - 'null' - string format: date-time lastSyncStatus: type: - 'null' - string endpoint: minLength: 1 type: string accessConditionsCount: type: integer format: int32 additionalProperties: false description: Integration details for 3rd party data used by Access Conditions discriminator: propertyName: integrationType mapping: CrowdStrike: '#/components/schemas/CrowdStrikeIntegrationDTO' WizIntegrationApi: '#/components/schemas/WizIntegrationDTO' AembitGeoIPCondition: '#/components/schemas/GeoIPIntegrationDTO' AembitTimeCondition: '#/components/schemas/TimeIntegrationDTO' TimeAccessConditionScheduleDTO: type: object properties: startTime: type: string format: date-span endTime: type: string format: date-span weekDay: $ref: '#/components/schemas/WeekDayDTO' additionalProperties: false AccessConditionV2DTOAccessConditionListDTO: type: object properties: page: type: integer description: Page of entities format: int32 perPage: type: integer description: Number of entities requested for the current page format: int32 order: type: - 'null' - string description: Ordering criteria used for the current page statusCode: type: integer description: HTTP Status Code of the response format: int32 recordsTotal: type: integer description: Total number of Access Conditions format: int32 accessConditions: type: - 'null' - array items: oneOf: - $ref: '#/components/schemas/AccessConditionV2DTO' - $ref: '#/components/schemas/CrowdStrikeAccessConditionDTO' - $ref: '#/components/schemas/WizAccessConditionDTO' - $ref: '#/components/schemas/GeoIPAccessConditionDTO' - $ref: '#/components/schemas/TimeAccessConditionDTO' description: Page of Access Conditions additionalProperties: false description: Page of Access Conditions securitySchemes: bearerAuth: type: http description: Authorization header using the Bearer scheme. scheme: bearer bearerFormat: Reference